使用OpenJDK 14模块化运行时出现TLS 1.3握手失败求助
Hey there, let's break down why your TLS 1.3 connections are failing when using a jlink-built runtime, even though they work perfectly fine with the full JDK/JRE or running the JAR directly.
The Root Cause
When you use jlink, it only packages modules that are explicitly declared in your module-info.java (plus their transitive dependencies). The key issue here is that elliptic curve (EC) cryptography support—critical for most TLS 1.3 handshake workflows—lives in the jdk.crypto.ec module, which isn't included in java.base or your current set of declared dependencies.
Without this module, your custom runtime can't send EC-based supported groups (like ECDHE curves) or ECDSA signature algorithms in the Client Hello. That's exactly what your Wireshark traces showed: only DHE groups and non-EC signature algorithms get sent, which most TLS 1.3 servers won't accept for a successful handshake.
The Simple Fix
- Update your
module-info.javato add a dependency onjdk.crypto.ec:module TlsHostInfo { requires java.base; requires javafx.controls; requires javafx.fxml; requires jdk.crypto.ec; // Add this line to include EC cryptography support opens certpackage.view to javafx.fxml; exports certpackage; } - Rebuild your jlink runtime with this updated module declaration. The build tool (or jlink itself) will now include the
jdk.crypto.ecmodule in your custom runtime image.
Why This Works for JARs but Not jlink
When you run your JAR with the full JDK/JRE, it includes all optional cryptography modules by default. jlink, however, follows a "minimal runtime" philosophy—it only includes what you explicitly ask for. By adding requires jdk.crypto.ec, you're telling jlink to include the EC cryptography components needed for TLS 1.3 to function properly.
Quick Verification
After rebuilding, run your application again and capture a Wireshark trace. You should now see:
- EC-based supported groups (like
x25519,secp256r1) listed in the Client Hello - ECDSA signature algorithms (like
ecdsa_secp256r1_sha256) included - A successful TLS 1.3 handshake with your target server
内容的提问来源于stack exchange,提问作者Cosmopolis

